Surprise Target: OpenAI Itself, China-Linked Hackers Faked ChatGPT Error Screens
Hey, Shiichan here! Today's story is about a fake ChatGPT error screen that was actually used to target OpenAI's own employees.
OpenAI NewsWhat was announced?
OpenAI's News page published its findings on SweetSpecter, a suspected China-based hacking group. In May 2024, the group ran a spear-phishing campaign against OpenAI employees, which came to light after a tip from a trusted external security team.
Why it matters
SweetSpecter has been active since 2023, previously targeting political entities across the Middle East, Africa, and Asia. This is the first time their targeting has been publicly confirmed to include a US-based AI company. The fact that AI companies themselves are becoming targets is something anyone working in this industry should take seriously.
What changes
OpenAI's security controls worked as intended: the malicious emails were blocked before reaching employees' corporate inboxes. OpenAI also assessed that whatever the attackers gained from using ChatGPT "did not appear to provide them with novel capabilities" beyond what's publicly available. Still, the fact that attackers are deliberately targeting AI company employees is now a concrete data point for everyone to factor into their own threat model.
Dive Deep
This campaign combined phishing with ChatGPT abuse in two parallel tracks:
- Spear-phishing: attackers posed as ChatGPT users and emailed a malicious attachment named "some problems.zip," which contained an LNK file
- Malware: running the LNK file displayed a fake ChatGPT error message while quietly installing SugarGh0st RAT in the background, giving attackers remote access to execute commands, capture screenshots, and exfiltrate data
- ChatGPT abuse: in parallel, the group used ChatGPT accounts to support offensive activity, researching known CVEs like Log4Shell, using the model for "LLM-informed reconnaissance" and vulnerability research, and getting help with scripting and malware development
- Social engineering polish: the attackers had ChatGPT generate multiple phrasing variations of a job-recruitment message they'd written, to make their phishing emails more convincing
- The targets were a small number of OpenAI employees, across both corporate and personal accounts
Wrap-up
- SweetSpecter, a suspected China-based hacking group, ran a spear-phishing campaign against OpenAI employees in May 2024
- The attack used a fake ChatGPT error screen as cover to install the SugarGh0st RAT malware
- In parallel, the group used ChatGPT accounts for vulnerability research, malware development help, and phishing message refinement
- OpenAI's email defenses blocked the malicious messages, and the information gained stayed within publicly available bounds
- A telling example of why "the AI company itself" is now on some attackers' target lists.